B BROCENT

HKMA

Cover image for Brocent IT blog post: The Pen-Test Requirement a Hong Kong Payments Firm Didn't See Coming

September 04, 2026 | 15 min

The Pen-Test Requirement a Hong Kong Payments Firm Didn't See Coming

A composite scenario from Hong Kong: a licensed payments firm faces a routine regulatory review asking for evidence of penetration testing, and finds a two-year-old PDF isn't evidence of anything current. What a maintained testing cadence changes, and where an IT partner's role stops.

Cover image for Brocent IT blog post: Why Hong Kong Companies Are Bundling MSP, MSSP, and HKMA/C-RAF Support Into One Contract

August 28, 2026 | 22 min

Why Hong Kong Companies Are Bundling MSP, MSSP, and HKMA/C-RAF Support Into One Contract

A research report on why Hong Kong companies — especially HKMA-regulated authorized institutions and their vendors — are bundling managed IT (MSP), managed security (MSSP), and HKMA cybersecurity/C-RAF regulatory support into a single RFP, what C-RAF's three components actually require, and where a vendor's honest role ends and the institution's own non-delegable regulatory accountability begins.